CVE-2025-7401

CRITICAL

WordPress Premium Age Verification <3.0.2 - Info Disclosure

Title source: llm

Description

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server which may make the exposure of sensitive information or remote code execution possible.

Exploits (2)

github WORKING POC 2 stars
by Nxploited · pythonpoc
https://github.com/Nxploited/CVE-2025-7401
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-7401

Scores

CVSS v3 9.8
EPSS 0.0071
EPSS Percentile 72.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-798
Status draft

Timeline

Published Jul 11, 2025
Tracked Since Feb 18, 2026